PubMed Health⌕ Search

SEARCH · PubMed Health

Results for “Privacy”

Explore indexed PubMed citations for clinical trials, systematic reviews and public health research. Read source abstracts and follow each citation to its original PubMed record.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7Linked to original sources

Patients' rights to privacy and dignity in the NHS.

AIM: To determine the extent to which patients' rights to privacy and dignity are respected in the NHS when judged against the seven factors of 'privacy and dignity' as outlined in the Essence of Care document (Department of Health (DH) 2001a). METHOD: An ethnographic methodology was used. Fieldwork took place over six months in three acute wards with surgical and medical patients in a large district NHS hospital, using non-participant observation, unstructured interviews with patients (n=55) and staff (n=12), and semi-structured interviews with patients (n=18) and staff (n=22). The culture and ward environment experienced by patients and staff in their everyday life were documented. FINDINGS: Medical and nursing staff had little awareness of the importance of the Human Rights Act 1998 and government documents about patients' privacy. They compromised the privacy and dignity of patients when judged against the Essence of Care benchmarks (DH 2001a). CONCLUSION: Educationalists, doctors, nurses and other practitioners should promote the importance of patients' privacy and dignity within the NHS. This issue should be integrated into undergraduate and postgraduate healthcare curricula.

Attitude of Health Personnel↗

HIPAA privacy standards raise complex implementation issues.

In November 1999, under the mandate of the Health Insurance Portability and Accountability Act (HIPAA) of 1996, HHS issued proposed standards to protect the privacy of electronically transmitted personal health information. With publication of the final standards due soon, healthcare organizations must prepare to implement new processes and information systems to comply with the HIPAA requirements. The privacy standards are intended to accomplish three broad objectives: define the circumstances in which protected health information may be used and disclosed, establish certain individual rights regarding protected health information, and require that administrative safeguards be adopted to ensure the privacy of protected health information. Among the required administrative safeguards are designation of a privacy officer, implementation of compliance training programs for all applicable staff, establishment of a complaint system, and implementation of appropriate sanctions for violations of privacy requirements.

Computer Security↗

The right to privacy and access to information about one's genetic origins.

The right to privacy contains different dimensions. Best known are the possibility to restrict the flow of personal information to others (limited access by others) and the right not to know certain information gathered about oneself. Since the privacy right is meant to protect the identity, self-image and personal life of the person, he should also have the right to know certain facts about himself. Information about genetic origins is potentially important for the child conceived by means of donor insemination because it tells him something about himself and about the relationships he has with others. However, the positive privacy right of the donor offspring may be overridden by the negative privacy right of the parents in which case they may keep the method of conception a secret and by the negative privacy of the donor which gives him the right to remain anonymous.

Civil Rights↗

Privacy enhancing techniques - the key to secure communication and management of clinical and genomic data.

OBJECTIVES: To introduce some of the privacy protection problems related to genomics based medicine and to highlight the relevance of Trusted Third Parties (TTPs) and of Privacy Enhancing Techniques (PETs) in the restricted context of clinical research and statistics. METHODS: Practical approaches based on two different pseudonymisation models, both for batch and interactive data collection and exchange, are described and analysed. RESULTS AND CONCLUSIONS: The growing need of managing both clinical and genetic data raises important legal and ethical challenges. Protecting human rights in the realm of privacy, while optimising research potential and other statistical activities is a challenge that can easily be overcome with the assistance of a trust service provider offering advanced privacy enabling/enhancing solutions. As such, the use of pseudonymisation and other innovative Privacy Enhancing Techniques can unlock valuable data sources.

Computational Biology↗

Conundrums with penumbras: the right to privacy encompasses non-gamete providers who create preembryos with the intent to become parents.

To date, five state high courts have resolved disputes over frozen preembryos. These disputes arose during divorce proceedings between couples who had previously used assisted reproduction and cryopreserved excess preembryos. In each case, one spouse wished to have the preembryos destroyed, while the other wanted to be able to use or donate them in the future. The parties in these cases invoked the constitutional right to privacy to argue for dispositional control over the preembryos; two of the five cases were resolved by relying on this right. The constitutional right to privacy protects intimate decisions involving procreation, marriage, and family life. However, when couples use donated sperm or ova to create preembryos, a unique circumstance arises: one spouse--the gamete provider--is genetically related to the preembryos and the other is not. If courts resolve frozen preembryo disputes that involve non-gamete providers based on the constitutional right to privacy, they should find that the constitutional right to privacy encompasses the interests of both gamete and non-gamete providers. Individuals who create preembryos with the intent to become a parent have made an intimate decision involving procreation, marriage, and family life that falls squarely within the the right to privacy. In such cases, the couple together made the decision to create a family through the use of assisted reproduction, and the preembryos would not exist but for that joint decision. Therefore, gamete and non-gamete providers should be afforded equal constitutional protection in disputes over frozen preembryos.

Contracts↗

The public health information infrastructure. A national review of the law on health information privacy.

Our objectives were to review and analyze the laws in the 50 states, the District of Columbia, and Puerto Rico that regulate the acquisition, storage, and use of public health data and to offer proposals for reform of the laws on public health information privacy. Virtually all states reported some statutory protection for governmentally maintained health data for public health information in general (49 states), communicable diseases (42 states), and sexually transmitted diseases (43 states). State statutes permitted disclosure of data for statistical purposes (42 states), contact tracing (39 states), epidemiologic investigations (22 states), and subpoena or court order (14 states). The survey revealed significant problems that affect both the development of fair and effective public health information systems and the protection of privacy. Statutes may be silent about the degree of privacy protection afforded, confer weaker privacy protection to certain kinds of information, or grant health officials broad discretion to disseminate personal information. Our proposals for law reform are based on a meeting of experts at the Carter Presidential Center under the auspices of the Centers for Disease Control and Prevention and the Council of State and Territorial Epidemiologists: (1) an independent data protection commission should be established, (2) health authorities should justify the collection of personally identifiable information, (3) subjects should be given basic information about data practices, (4) data should be held and used in accordance with fair information practices, (5) legally binding privacy and security assurances should attach to identifiable health information with significant penalties for breach of these assurances, (6) disclosure of data should be made only for purposes consistent with the original collection, and (7) secondary uses beyond those originally intended by the data collector should be permitted only with informed consent.

Computer Security↗

The social life of genes: privacy, property and the new genetics.

With the advent of the Human Genome Project and widespread fears over human cloning and medical privacy, a number of states have moved to protect genetic privacy. Oregon's unique Genetic Privacy Act of 1995, which declared that an individual had property rights to their DNA, has provoked national and international interest and controversy. This paper critically reviews the literature on genetic privacy and gene patenting from law, philosophy, science and anthropology. The debate in Oregon, from 1995 to 2001, illustrates many of the key issues in this emerging area. Both sides of the debate invoke the property metaphor, reinforcing deterministic assumptions and avoiding more fundamental questions about the integrity of the body and self-identity. The anthropological critique of the commodification of the body, and the concept of 'embodiment' are useful in analyzing the debate over DNA as property.

Anthropology↗

Privacy protection and population-based health research.

In this article we discuss obstacles of privacy protection measures to population-based health research and we give suggestions for policies facilitating this research as well as protecting the privacy of the patient. Privacy is the capacity of the individual to determine which information is communicated to whom. Population-based health research is research among human populations and refers to health services research, medical sociology, epidemiology, occupational health, social dentistry, family medicine a.o. Although population-based health research focuses on groups and not on individuals, the access to health and other vital records and the possibility to identify the individuals for subsequent interview and study are of crucial importance. In various countries the legislation regarding privacy protection requires that medical records should not be disclosed unless with the consent of the individual. Therefore it forms a major obstacle to population-based health research as this research is very difficult to carry out if prior consent is required in order for the investigator to have access to medical records. Population-based health research has given us important knowledge about the etiology of many diseases and the effect of interventions. In the case of population-based health research disclosure of patient information without the explicit patient consent should be seriously considered. This disclosure should only be permitted if an institutional board has studied the project plans of the investigators and has carefully watched the privacy aspects of their studies.

Australia↗

The Health Insurance Portability and Accountability Act: security and privacy requirements.

The security and privacy requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and their implications for pharmacy are discussed. HIPAA was enacted to improve the portability of health care insurance for persons leaving jobs. A section of the act encourages the use of electronic communications for health care claims adjudication, mandates the use of new standard code sets and transaction sets, and establishes the need for regulations to protect the security and privacy of individually identifiable health care information. Creating these regulations became the task of the Department of Health and Human Services. Regulations on security have been published for comment. Regulations on privacy and the definition of standard transaction sets and code sets are complete. National identifiers for patients, providers, and payers have not yet been established. The HIPAA regulations on security and privacy will require that pharmacies adopt policies and procedures that limit access to health care information. Existing pharmacy information systems may require upgrading or replacement. Costs of implementation nationwide are estimated to exceed $8 billion. The health care community has two years from the finalization of each regulation to comply with that regulation. The security and privacy requirements of HIPAA will require pharmacies to review their practices regarding the storage, use, and disclosure of protected health care information.

Confidentiality↗

Medical information privacy and the conduct of biomedical research.

Profound changes in the health care delivery system, the increasing pervasiveness of information technology, and dramatic advancements in research in human genetics are intensifying public concerns about the privacy of medical information. The author argues that some of these concerns, such as the fear that medical data could be used to deny health insurance or employment, are "pragmatic" and can be dealt with through the political process. But other, "ideologic" concerns tend to generate strong emotions and political positions that impede rational discourse and confound attempts to seek workable compromises. He stresses that the progress of medicine has long depended on studies of collections of empirical data about individuals, and discusses the federal oversight of research involving human subjects, including provisions in place to protect their privacy and maintain the confidentiality of data while at the same time permitting necessary access to data for research. He suggests that since every individual benefits from the accumulated medical knowledge base, everyone should contribute to the ongoing expansion and renewal of that base. The author then states nine principles crafted at the Association of American Medical Colleges to guide its thinking and advocacy efforts regarding medical-information privacy issues. (For example, "the free flow of identifiable medical information within the boundaries of the health care system is essential to the optimum provision of patient care and its payment.") He acknowledges that the flows and uses of identifiable patient information within our complex health care and research systems are bewildering and hard to explain to the public, which is deeply concerned about privacy in general, and especially medical information privacy. How to address this concern and at the same time protect the completeness, accuracy, and integrity of the medical record? The author offers no specific answers beyond those embodied in the AAMC principles, but maintains that a satisfactory solution will come only from carefully crafted federal legislation that creates a comprehensive, uniform, and effective system of workable protections of the confidentiality of medical information, while protecting the access needed to puruse the nation's ambitious agenda in health research.

Confidentiality↗

A smart-card-enabled privacy preserving E-prescription system.

Within the overall context of protection of health care information, privacy of prescription data needs special treatment. First, the involvement of diverse parties, especially nonmedical parties in the process of drug prescription complicates the protection of prescription data. Second, both patients and doctors have privacy stakes in prescription, and their privacy should be equally protected. Third, the following facts determine that prescription should not be processed in a truly anonymous manner: certain involved parties conduct useful research on the basis of aggregation of prescription data that are linkable with respect to either the patients or the doctors; prescription data has to be identifiable in some extreme circumstances, e.g., under the court order for inspection and assign liability. In this paper, we propose an e-prescription system to address issues pertaining to the privacy protection in the process of drug prescription. In our system, patients' smart cards play an important role. For one thing, the smart cards are implemented to be portable repositories carrying up-to-date personal medical records and insurance information, providing doctors instant data access crucial to the process of diagnosis and prescription. For the other, with the secret signing key being stored inside, the smart card enables the patient to sign electronically the prescription pad, declaring his acceptance of the prescription. To make the system more realistic, we identify the needs for a patient to delegate his signing capability to other people so as to protect the privacy of information housed on his card. A strong proxy signature scheme achieving technologically mutual agreements on the delegation is proposed to implement the delegation functionality.

Algorithms↗

Prying questions about privacy in a nosy world.

The subject of this article is privacy and its relationship to the activities of health care organizations. Privacy is a good quality that each individual may possess. The quality of an individual's privacy is a personal determination. Although everyday life requires that we attempt to understand and protect the privacy of others, our efforts may be unsatisfactory despite our best intentions. If an individual believes that his or her privacy has been invaded, then it has been; no determination or opinion of a third party can alter that fact.

Clinical Laboratory Information Systems↗

Employee benefit plans need to protect privacy of participant information.

Employee benefit plans need to examine their privacy policies and practices. Three areas of privacy compliance plan administrators should review are the HIPAA privacy regulations, state law claims against employee benefit plans for invasion of privacy and Web site privacy policies.

Computer Security↗

Complying with the Health Insurance Portability and Accountability Act. Privacy standards.

The Privacy Rule: Limits the use and disclosure of PHI to purposes of treatment, payment, or routine health care operations. Requires covered entities to provide advance notice to the public of its policy governing disclosure of PHI. Requires entities covered by the Standard to secure general client consent to use and to disclose PHI for treatment, payment, or routine health care operations and to obtain specific client authorization to use or to disclose PHI for all other purposes unless the disclosure is specifically permitted without consent or authorization (e.g., a covered entity may disclose PHI to a health care oversight agency such as the Office of the Inspector General without first obtaining client authorization). In certain situations, a covered entity need only obtain client agreement to disclose PHI which may be oral or inferred from the circumstances surrounding the disclosure. For example, a covered entity could disclose PHI to a relative caring for the individual who is the subject of the health information. Expects covered entities to take measures to protect PHI from both inadvertent and deliberate misuse and disclosure. Requires, except in certain circumstances, the amount of PHI disclosed on any occasion to be limited to the minimum necessary to achieve the purpose of the disclosure. Gives individuals more control of their health information by permitting them to review and amend health information pertaining to themselves and to demand an accounting of persons to whom their health information has been disclosed. Establishes terms under which a covered entity may disclose PHI to a business associate. Permits states to maintain state laws that are more stringent than the Privacy Rule. The statute provides for significant civil and criminal penalties for failure to comply with the Standards. Violations are punishable by fines as much as $250,000 and 10 years imprisonment. The HHS, Office of Civil Rights is charged with enforcing the Standards. The HHS is expected to issue a single Enforcement Rule applicable to all three of the HIPAA Administrative Simplification Standards. Many worksite records will not be protected under the HIPAA Privacy Rule because employers are not covered entities and few occupational health professionals meet the criteria of being considered a covered entity. Nevertheless, occupational health professionals need to be knowledgeable about the application of HIPAA in the occupational health care setting. Furthermore, given that the Rule does not preempt state privacy laws that are more stringent than the Standards, occupational health professionals should monitor legislative activity related to privacy in the states in which they practice. To date, Oregon, Texas, and New Jersey have broadened HIPAA's definitions to create more covered entities and services.

Algorithms↗

Future of security and privacy in medical information.

Today, issues of privacy and confidentiality in healthcare are dealt largely informally. Little legislation exists, and the awkwardness of accessing paper records makes violations of patients' privacy sporadic. As healthcare institutions move towards a future where all information is kept in an Electronic Medical Record (EMR), the casual attitudes that are prevalent will be in conflict with the desires and expectations of the patients. Legislation has been passed to make the holders of medical data responsible for securely protecting the patients privacy. Specific implementation guidelines are still lacking. There is much institutional resistance to the adoption of rigorous rules, but we expect that in the near future reliable procedures will have to be implemented to comply both with legal guidelines and patient's expectations. After introducing the issue more precisely we provide an overview over the concepts needed to understand the roles of technology of privacy and security and the people that must manage the technology. We then discuss the components of secure EMR systems and will point out where adequate technology exists and where future improvements are essential. We conclude with some advice to healthcare management facing the demands for security and privacy that the future will bring.

Computer Security↗

The PRIDEH project: taking up privacy protection services in e-health.

PRIDEH (Privacy Enhancement in Data Management in e-Health) is a project that runs for two years and is partly funded by the European Commission. The focus of PRIDEH is on the stimulation of the take-up of privacy enhancing technologies within the health domain. Privacy enhancing technologies build upon available cryptographic and communication technologies. The concept of privacy enhancing services delivery through the use of intermediary trusted third parties has already been described in literature but rarely turned into practice. A number of limited PET (Privacy Enhancing Technologies) applications exist in closed domains. The very few existing solutions are not based on an independent TTP (Trusted Third Party) concept which renders their trustworthiness questionable. PRIDEH wants to enhance the take-up of PET delivery based on sound TTP principles in the domain of healthcare.

Access to Information↗

The PRIDEH project: taking up privacy protection services in eHealth.

PRIDEH (Privacy Enhancement in Data Management in e-Health) is a project that runs for two years and is partly funded by the European Commission. The focus of PRIDEH is on the stimulation of the take-up of privacy enhancing technologies within the health domain. Privacy enhancing technologies build upon available cryptographic and communication technologies. The concept of privacy enhancing services delivery through the use of intermediary trusted third parties has already been described in literature but rarely turned into practice. A number of limited PET (Privacy Enhancing Technologies) applications exist in closed domains. The very few existing solutions are not based on an independent TTP (Trusted Third Party) concept which renders their trustworthiness questionable. PRIDEH wants to enhance the take-up of PET delivery based on sound TTP principles in the domain of healthcare.

Computer Security↗

HIPPA privacy regulations: practical information for physicians.

After much debate and controversy, the Bush administration announced on April 12, 2001, that it would implement the Health Insurance Portability and Accountability Act (HIPAA) privacy regulations issued by the Clinton administration in December of 2000. The privacy regulations became effective on April 14, 2001. Although the regulations are considered final, the Secretary of the Department of Health and Human Services has the power to modify the regulations at any time during the first year of implementation. These regulations affect how a patient's health information is used and disclosed, as well as how patients are informed of their privacy rights. As "covered entities," physicians have until April 14, 2003, to comply fully with the HIPAA privacy regulations, which are more than 1,500 pages in length. This article presents a basic overview of the new and complex regulations and highlights practical information about physicians' compliance with the regulations. However, this summary of the HIPAA privacy regulations should not be construed as legal advice or an opinion on specific situations. Please consult an attorney concerning your compliance with HIPAA and the regulations promulgated thereunder.

Journal Article↗